Courseiva

CISM Information Security Risk Management Practice Question

A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?

⚠ Common exam trap

The trap here is choosing immediate remediation or quietly adjusting the appetite statement, when the governance-correct first step is escalating the appetite breach to the accountable executives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the residual risk to senior management as a risk above the approved appetite.

Risk appetite defines the amount of risk leadership is willing to accept in pursuit of objectives. When residual risk exceeds that boundary, the information security manager's first obligation is to escalate the exception to senior management, who own the decision to remediate, accept, or adjust strategy. Acting unilaterally or rewriting the appetite statement would bypass proper governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document the residual risk in the risk register and continue monitoring it on the normal reporting cycle.

    Why it's wrong here

    Routine documentation and monitoring are appropriate for risks within appetite, not for a high residual risk that breaches a stated tolerance for payment data. Treating an appetite violation as business as usual delays necessary executive action. The manager must escalate the exception promptly so leadership can decide on treatment before the exposure results in a payment data incident.

  • ✓

    Escalate the residual risk to senior management as a risk above the approved appetite.

    Why this is correct

    When residual risk exceeds the documented risk appetite, the gap is a governance issue that must be escalated to the risk owners and senior management who set the appetite. They are accountable for deciding whether to fund additional controls, accept the deviation, or change business plans. Informing them first ensures the decision is made at the appropriate authority level.

  • ✗

    Revise the risk appetite statement so the current residual risk falls within acceptable limits.

    Why it's wrong here

    Adjusting the appetite statement to legitimize an existing exposure is reverse-engineering governance to avoid a difficult conversation. Risk appetite is set by senior leadership based on business strategy, not by the security manager to match current conditions. Doing this would conceal a genuine gap in payment data protection and undermine the credibility of the entire risk management program.

  • ✗

    Immediately implement additional controls and then report the change in risk level.

    Why it's wrong here

    Implementing controls without approval may exceed budget, disrupt payment operations, and preempt the risk owner's authority to choose among treatment options. While remediation may ultimately be the answer, the manager's first duty is to surface the appetite breach so the accountable executives can direct the response and authorize any spending on payment environment safeguards.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.